GoogleContainerTools / GoogleContainerTools/skaffold

Skaffold build using Kaniko on GKE

Open
#4,797 2 comments 1 reaction 0 assignees View on GitHub
build/kaniko help wanted kind/friction priority/p1
Dominant language
Go
Stars
15.9k
Forks
1.7k
Avg merge
3d 9h
Merged PRs (30d)
10

Description

I'm using Skaffold with a Kaniko build step on GKE and am wondering why the need for the `kaniko-secret`.

If I'm in GKE and the default SA used has permissions to push to my GCR repo why do I need to also supply SA keys via the kaniko-secret?

I see that things are working without the secret if Workload Identity is enabled but what about clusters not yet migrated to Workload Identity? https://github.com/GoogleContainerTools/skaffold/issues/3468

The only way I found to get it working is with the following instructions and `skaffold.yaml`.

### Instructions:
1. Create SA with `Starage Admin`
2. Download keys
3. Rename keys to kaniko-secret
4. `kubectl create secret generic kaniko-secret --from-file=kaniko-secret`

### skaffold.yaml
```yaml
apiVersion: skaffold/v2beta7
kind: Config
metadata:
name: my-image
build:
artifacts:
- image: gcr.io/my-repo/my-image
kaniko:
cache: {}
cluster:
pullSecretName: kaniko-secret
```

How can I make this work with the default SA and not have to add secondary keys?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.